GHSA-34jx-wx69-9x8v · Severity: medium · Ecosystem: go — Symlink Attack in kubectl cp
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user’s machine when kubectl cp is called, limited only by the system permissions of the local user. The untar function can both create and follow symbolic links. The issue is resolved in kubectl v1.11.9, v1.12.7, v1.13.5, and v1.14.0.
Conclusion & alert: CVE-2019-1002101 is rated Moderate Risk (59.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 49.94%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-27 | 50.52% | 49.94% | -0.58% |
| 2 | 2026-05-22 | 49.27% | 50.52% | +1.25% |
| 3 | 2026-03-18 | — | 49.27% | — |
Full EPSS history (62 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 3.0 | MEDIUM |
|
0.5 | 5.9 | [email protected] |
| 5.5 | 3.0 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 5.8 | 2.0 | MEDIUM |
|
8.6 | 4.9 | [email protected] |
GHSA-34jx-wx69-9x8v · Severity: medium · Ecosystem: go — Symlink Attack in kubectl cp
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2019-1002101 unimportant priority: Debian including 1 source packages (kubernetes), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-1002101 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-1002101 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2019-1002101/ |
ubuntu
|
medium | CVE-2019-1002101 medium priority: Ubuntu including 1 source packages (kubernetes), 18 status rows across 18 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): ignored 10, DNE 4, not-affected 4. | https://ubuntu.com/security/CVE-2019-1002101 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| kubernetes | kubernetes | >= 1.11.0, < 1.11.9 | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
| kubernetes | kubernetes | >= 1.12.0, < 1.12.7 | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
| kubernetes | kubernetes | >= 1.13.0, < 1.13.5 | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
| kubernetes | kubernetes | 1.14.0 | cpe:2.3:a:kubernetes:kubernetes:1.14.0:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 3.9 | cpe:2.3:a:redhat:openshift_container_platform:3.9:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 3.10 | cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 3.11 | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* |